First-Party-Only Traffic WAS: Re: First-Party-Only cookies
Kevin Chadwick <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
I apologise upfront as I haven't looked into the RFC properly at all. I wonder if this idea could be extended so that I can instruct client side that all traffic should originate from the primary domain? Or is that pointless as TLS *should* guarantee this anyway. I guess it could be stripped from plain text but wonder if it would still be of any use? Thinking about it that already exists as the content origin policy directive, correct? -- KISSIS - Keep It Simple So It's Securable